Plagiarism and the Security Professional part 2

Monday, September 19, 2011

Craig S Wright


Internet Piracy, Contraband, Counterfeit Products, Plagiarism and Copyright and the “Security Professional” Part 2

It may often occur that works offered over the Internet, either by a service provider or its subscribers, is included within the copyright owned by a third party who has not sanctioned the works distribution.

In some instances, a service provider may be liable for a copyright infringement using its service and systems. Access to copyrighted material without license is illegal in itself. It is analogous to receiving stolen property.

The damage done through plagiarism and the deception it entails damages not just those involved, but also the entire information security community when it is one of our own.

The legal issues with respect to copyright and piracy

In the UK, copyright law is governed through the "Copyright, Designs and Patents Act 1988” (the “1998 Act”) and the ensuing decisions of courts. The Australian position [2] mirrors that of the UK where protection of a work is free and automatic upon its creation and differs from the position in the US, where work has to be registered to be actionable.

While some divergences may be found, Australian copyright law largely replicates the frameworks in place within the US and UK. The copyright term is shorter than these jurisdictions in Australia being the creator’s life plus 50 years whereas the UK has a term of 70 years from the end of the calendar year in which the last remaining author of the work dies for literary works. As co-signatories to the Berne Convention, most foreign copyright holders are also sheltered in both the UK and Australia.

The 1988 Act catalogues the copyright holder’s exclusive rights as the rights to copy, issue copies of the work to the public, perform, show or play in public and to make adaptations. An ephemeral reproduction that is created within a host or router is a reproduction for the intention of copyright law. Though, there appears to be no special right to broadcast a work over a network, a right is granted in Section 16(1)(d) to broadcast the work or include it in a cable program service.

The notion of “broadcast” is restricted to wireless telegraphy receivable by the general public. Interactive services are explicitly excluded from the designation of “cable program service” (S.7 (2)(a)). A proviso making an individual an infringer of the act in the event of remote copying has been defined to encompass occasions where a person who transmits the work over a telecommunications system [3] knowing or reasonably believing that reception of the transmission will result in infringing copies to be created.

The law contains provisions imposing criminal penalties and civil remedies for making, importing or commercially trading in items or services designed to thwart technological copyright protection instruments, and sanctions against tampering with electronic rights management information and against distributing or commercially dealing with material whose rights management information has been tampered with. [4]
There are several legislative limitations on the scope of exclusive rights under UK law [5]. Liability is also possible for secondary infringement including importing and distributing infringing copy prepared by a third party. The scope of the exclusive rights of the copyright owner is extensive enough to include an ISP or ICH that utilizes or consciously allows another to its system in order to store and disseminate unauthorized copies of copyright works. This situation would create the risk of civil action. A contravention could constitute a criminal offence if a commercial motivation for copyright infringement could be demonstrated.

The Australian High Court decision in Telstra Corporation Ltd v Australasian Performing Rights Association Limited [6] imposed primary liability for copyright infringement on Telstra in respect of music broadcast over a telephone “hold” system. A large part of the decision concentrated on the definition of the diffusion right in Australia. [7]

It follows from this decision that if an ISP broadcasts copyright works to in the general course of disseminating other materials through the Internet, that diffusion is a “transmission to subscribers to a diffusion service” as defined by the Australian Copyright Act. It consequently emerges that an ISP may be directly liable for an infringement of copyright caused by that transmission under Australian common law for the infringements of its customers. [8]
A determination as to whether a message using telecommunications is “to the public [9] will likely hinge on whether the message is made “openly, without concealment” [33] to a sufficiently large number of recipients. No case has attempted to quantify a specific cut-off point.

In Moorhouse v. University of New South Wales, [10] a writer initiated a “test case” asserting copyright infringement against the University of New South Wales. The University had provided a photocopier for the function of allowing photocopying works held by the university’s library. A chapter of the plaintiff’s manuscript was copied by means of the photocopier.

The library had taken rudimentary provisions to control the unauthorized copying. No monitoring of the use of the photocopier was made. Further, the sign located on the photocopier was unclear and was determined by the Court to not be “adequate [11]. The Australian High Court held that, whilst the University had not directly infringed the plaintiff’s copyright, the University had sanctioned infringements of copyright in that the library had provided a boundless incitement for its patrons to duplicate material in the library. [12]

Intermediaries are frequently in the same position as the University. They provide rudimentary monitoring of client infringements at best. In July 1997, the Australian Attorney-General published a discussion paper [13] that proposed a new broad-based technology-neutral diffusion right as well as a right of making available to the public. This provides the position where direct infringement by users of a peer-to-peer (P2P) file-sharing network would be covered in Australian law in a manner comparable to the US position in both Napster and Grokster [14].

Mann and Belzley’s position holds the least cost intermediary liable is likely to be upheld under existing UK, US and Australian law. The positions held by the court in Telstra v Apra and Moorhouse v UNSW [15] define the necessary conditions to detail public dissemination and infringement through a sanctioned arrangement.

The public dissemination of music clips on a website could be seen as being analogous to the copying of a manuscript with the ISP's disclaimer being held as an inadequate control. It is clear that the provision of technical controls, monitoring and issuing of take down notices by the ISP would be far more effective at controlling copyright infringement than enforcing infringements against individuals.

Several cases have occurred in the US involving ISPs or other service providers that hosted copyright material made available to those accessing the site. A significant decision was made in Religious Technology Center v Netcom On–line Communication Services, Inc [16].

The case involved the posting of information online which was disseminated across the Internet. The postings were cached by the hosting provider for several days, and robotically stored by Netcom’s system for 11 days. The court held that Netcom was not a direct infringer in summary judgment [17].

It was held that the mere fact that Netcom’s system automatically made transitory copies of the works did not constitute copying by Netcom. The court furthermore discarded arguments that Netcom was vicariously liable. The Electronic Commerce (EC Directive) Regulations 2002 [18] warrants that the equivalent outcome would be expected in the UK [19].

The US Congress has acted in response with a number of statutes by and large that are intended to protect the intermediary from the threat of liability [20]. The Digital Millennium Copyright Act (DMCA) [21] envelops the possibility of liability from copyright liability. The DMCA is prepared such that it exempts intermediaries from liability for copyright infringement whilst they adhere to the measures delineated in the statute.

These in the main compel them to eliminate infringing material on the receipt of an appropriate notification from the copyright holder. These protections only apply to the US. With the globalization of service offerings and the introduction of cloud computing, extra-jurisdictional issues still arise. This makes it more critical that intermediaries act to ensure that they have created contracts that can be enforced and that they maintain a suitable monitoring regime.

The “fair dealing” exceptions provided in the copyright laws of the UK are a great deal more restrictive than the “fair use” exceptions held by the US. If the Netcom [22] trial was held in the UK, it would have to deal with the explicit requirements of Section 17 of the UK’s 1988 Act that defines copying in a meaner that includes storage by electronic means. The act also includes provisions that cover the creation of transient or incidental copies. These provisions make it probable that the result in the UK would have varied from that in the US at least in the first instance.

The inclusion of storage differentiates ISPs and ICPs from telephone providers aligning them closer to publishers. AN ISP or ICP could attempt to argue a similarity to a librarian over that of a publisher. The statutory provisions providing certain exemptions from liability for libraries under the 1988 Act and accompanying regulations are unlikely to apply to an ISP as the ability for a librarian to make copies is controlled under strict conditions. It is doubtful that these conditions could be met by either an ISP or ICP.

An ISP or ICP would rarely have complete (or even near complete) knowledge of the content held on their systems. In contrast, even the largest of libraries has a complete catalogue of the materials on its shelves. Both the common law of the UK and Australia divide defamation by publication into three classes. This includes the publisher who is strictly liable for publishing defamatory material.

As the distributer of the material, they are presumed to know its content and are not at liberty to use the defense of innocent dissemination. Next are the subordinate publishers. These parties are also known as secondary distributors. The subordinates are liable for publishing defamatory material to a limited extent. The defense of innocent dissemination can be used if the party can demonstrate that they had no knowledge of the materials content. Lastly, there is the class of those who are not publishers and are not liable for publication.

If an ICP [Internet Content Provider] or ISP is to claim protection as a publisher, it is illogical to except the last class of defense to apply to them. In the first class, they are liable. This leaves only the option of claiming innocent dissemination as a secondary distributor. If it can be demonstrated that the ISP or ICP monitors the content they maintain in any way or that the content was brought to the attention of the ICP, this defense will fail.

There are both similarities and differences between the UK common law and US defamation code. The US also creates three classes, primary publishers, secondary publishers (also called distributors) and parties who are not publishers. Primary publishers closely represent the UK common law class of publisher and do not receive protection through limited liability provisions in the Federal code. Secondary publishers do have some limitations as to the liability they can face. There are few cases that have considered the liability of ICPs.

These have so far placed the ICP in the same place as authors of printed material. This approach does create interesting possibilities as can be seen from Macquarie Bank Ltd v Berg [23]. This case involved an ex parte application for an injunction to restrain the publication of material. The intent was to stop publication via a Web site hosted in the US. The result was that New South Wales Supreme Court Justice Simpson declared:

“An injunction to restrain defamation in NSW is designed to ensure compliance with the laws of NSW, and to protect the rights of plaintiffs, as those rights are defined by the law of NSW. Such an injunction is not designed to superimpose the law of NSW relating to defamation on every other state, territory and country of the world. Yet that would be the effect of an order restraining publication on the Internet”
Modern peer-to-peer networks have separated the network from software with a decentralized indexing process [24] in an attempt to defend themselves from an exposure to vicarious liability as in Napster [25]. The methods suggested by Kraakman’s analysis of asset insufficiency [14], have led ICPs and ISPs to become judgment proof, thus restraining the effectiveness of sanctions even against the intermediaries.

It seems natural to expect as the technology develops that it in practice will be so decentralized as to obviate the existence of any intermediary gatekeeper that could be used to shut down the networks [26].
The success of modern peer to peer networks has resulted in the content industry targeting those individual copyright infringers who use peer-to-peer networks to disseminate or download copyrighted material [27]. Existing peer-to-peer networks and software permits the capture of sufficient information concerning individuals who attach to the network to identify the degree of infringement and possibly who is responsible [13].

Recent advances to the P2P networking protocols have allowed users to screen their identity removing the ability for copyright holders to bring their claims to court [1]. As copyright infringement evolves, it will become more improbable to expect a solution through prosecuting individual users [28].

This type of action is currently being fought in the EU with Danish ISP, Tele2, planning to fight a court order requiring it to block access to the Bit-Torrent website known as Pirate Bay. The ISP has cut off access to the site for its customers but other ISPs in Denmark are yet to receive letters requesting that they also prevent their users from accessing the website. The International Federation of the Phonographic Industry (IFPI) has stated that it plans to dispatch the letters this week (Feb, 2008)[29].

Jurisdictional issues will play a large role in the determination of a case. The location of the plaintiff as well as the increasingly global nature of Internet commerce introduces a level of uncertainty to both the ISP and ICP as well as the author of information. It is insufficient for the ICP to consider the jurisdiction in the locality where they are incorporated in alone. Rather, it is necessary to also consider the possible range of jurisdictions from which clients of the ICP may operate.

Some jurisdictions, such as Australia, seek to limit the reach of their influence. Other jurisdictions such as Florida in the USA have taken the opposite approach. Florida’s ‘Long Arm’ statute permits jurisdiction over those “engaged in substantial and not isolated activity” within the state. When comparing the approaches of the Florida and NSW state courts, we see a radically diffident approach to determining jurisdiction.


